Title :
Global abnormal correlation analysis for DDoS attack detection
Author :
Li, Zong-lin ; Hu, Guang-Min ; Yang, Dan
Author_Institution :
Key Lab. of Broadband Opt. Fiber Transm. & Commun. Networks, Univ. of Electron. Sci. & Technol. of China, Chengdu
Abstract :
Distributed detection mechanism of DDoS (distributed denial of service) attack is often achieved by the corporation between many detection nodes, its final detection result largely depends on the judgements of local nodes. While DDoS attack flows are distributed enough in many links, itpsilas hard to derive exact judgement for every node only by the information collecting from local, consequently impact the performance of whole detection system. Despite DDoS attack could be unaware in local, the inherent dependency among attack flows transiting in many links do exists. This paper proposes an abnormal correlation analysis method from a global perspective for DDoS attack detection deploying in the backbone network, via extracting anomalous space from network-wide traffic, analyzing the correlation across them, revealing attacks through the change of correlation. Analyzing the network-wide traffic simultaneously helps to discover attacks indistinctive in single node; moreover, utilizing the correlation between attacks, rather than the volume of attack purely, makes our method can overcome the difficulties in detecting relatively small attacks comparing to the tremendous traffic in backbone network. Simulations demonstrate that our method has benefit of detecting DDoS attacks while they are small in single link and is superior to other methods proposed in present literatures.
Keywords :
computer networks; principal component analysis; telecommunication security; telecommunication traffic; DDoS attack detection; abnormal correlation analysis method; backbone network; backbone network traffic; distributed denial of service attack; distributed detection mechanism; global abnormal correlation analysis; network-wide traffic; Computer crime; Computer networks; Data flow computing; Distributed computing; Failure analysis; Performance analysis; Principal component analysis; Spine; Telecommunication traffic; Traffic control;
Conference_Titel :
Computers and Communications, 2008. ISCC 2008. IEEE Symposium on
Conference_Location :
Marrakech
Print_ISBN :
978-1-4244-2702-4
Electronic_ISBN :
1530-1346
DOI :
10.1109/ISCC.2008.4625614